American Bar Association
bd_a594d6029eaa462f · schema v1 · pii pii-v1
Full breach record for American Bar Association →The American Bar Association (ABA) notified the California Attorney General of a data breach where an unauthorized third party gained access to its network starting on or about March 6, 2023. The ABA detected unusual activity on March 17, 2023. The incident involved the acquisition of usernames and salted/hashed passwords for online accounts on the old ABA website (pre-2018) and the ABA Career Center (since 2018). No plain-text passwords were exposed. The ABA activated its incident response plan, retained cybersecurity experts, removed the attacker, and reviewed network security configurations.
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_ebe4be8808814e12Delaware State AGfiled 2023-04-20Candidate
- bd_1919aeff1b67bdfcWashington State AGfiled 2023-04-21(1d gap)Verified
- bd_9b4a53df43e28d25Oregon State AGfiled 2023-04-21(1d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-565797
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 20, 2023
- Raw hash
- eda29ed1d621229394ca48842ebd6439905431751450187782e4d8971d8b433e
Reporting entity
- Name
- American Bar Associationnorm: american bar
- Domain
- americanbar.org
Victim entity
- Name
- American Bar Associationnorm: american bar
- Domain
- americanbar.org
Incident
- Discovered
- Mar 17, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- CREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
Compliance
- Time to disclose
- 5 weeks(34 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.